5.1

CVSS4.0

CVE-2025-4655 -

SSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows template editors …

πŸ“… Published: Aug. 9, 2025, 4:46 a.m. πŸ”„ Last Modified: Aug. 12, 2025, 7:48 a.m.

5.3

CVSS4.0

CVE-2025-4581 -

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows a pre-authentication blind SSRF vulnerability in the portal-set…

πŸ“… Published: Aug. 9, 2025, 4:14 a.m. πŸ”„ Last Modified: Aug. 12, 2025, 7:47 a.m.

6.7

CVSS4.0

CVE-2025-55149 - Path Traversal Vulnerability in PDF Review Function (CWE-22)

Tiny-Scientist is a lightweight framework for automating the entire lifecycle of scientific researchβ€”from ideation to implementation, writing, and review. In versions 0.1.1 and below, a critical path traversal vulnerability has been identified in the review_paper function in backend/app.py. The vul…

πŸ“… Published: Aug. 9, 2025, 2:02 a.m. πŸ”„ Last Modified: Aug. 12, 2025, 11:47 a.m.

4.2

CVSS3.1

CVE-2025-55013 - Assemblyline 4 Service Client: Arbitrary Write through path traversal in Client code

The Assemblyline 4 Service Client interfaces with the API to fetch tasks and publish the result for a service in Assemblyline 4. In versions below 4.6.1.dev138, the Assemblyline 4 Service Client (task_handler.py) accepts a SHA-256 value returned by the service server and uses it directly as a local…

πŸ“… Published: Aug. 9, 2025, 2:02 a.m. πŸ”„ Last Modified: Aug. 12, 2025, 2:15 p.m.

7.1

CVSS3.1

CVE-2025-55008 - AuthKit React Router: Sensitive auth data rendered in HTML

The AuthKit library for React Router 7+ provides helpers for authentication and session management using WorkOS & AuthKit with React Router. In versions 0.6.1 and below, @workos-inc/authkit-react-router exposed sensitive authentication artifacts β€” specifically sealedSession and accessToken by retur…

πŸ“… Published: Aug. 9, 2025, 2:02 a.m. πŸ”„ Last Modified: Aug. 12, 2025, 11:47 a.m.

7.1

CVSS3.1

CVE-2025-55009 - AuthKit: Sensitive auth data rendered in HTML

The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix. In versions 0.14.1 and below, @workos-inc/authkit-remix exposed sensitive authentication artifacts β€” specifically sealedSession and accessToken β€” by returning them …

πŸ“… Published: Aug. 9, 2025, 2:02 a.m. πŸ”„ Last Modified: Aug. 12, 2025, 11:47 a.m.

4.3

CVSS3.1

CVE-2025-55006 - Frappe Learning Holds Potential for Malicious SVG Upload in Image Upload Feature

Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image upload functionality did not adequately sanitize uploaded SVG files. This allowed users to upload SVG files containing embedded JavaScript or other potentially malicious content. M…

πŸ“… Published: Aug. 9, 2025, 2:01 a.m. πŸ”„ Last Modified: Aug. 12, 2025, 11:47 a.m.

5.7

CVSS3.1

CVE-2025-55003 - OpenBao Login MFA Bypasses Rate Limiting and TOTP Token Reuse

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao's Login Multi-Factor Authentication (MFA) system allows enforcing MFA using Time-based One Time Password (TOTP). Due to norma…

πŸ“… Published: Aug. 9, 2025, 2:01 a.m. πŸ”„ Last Modified: Aug. 12, 2025, 11:47 a.m.

6.5

CVSS3.1

CVE-2025-55001 - OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao allowed the assignment of policies and MFA attribution based upon entity aliases, chosen by the underlying auth method. When …

πŸ“… Published: Aug. 9, 2025, 2:01 a.m. πŸ”„ Last Modified: Aug. 12, 2025, 11:47 a.m.

6.5

CVSS3.1

CVE-2025-55000 - OpenBao TOTP Secrets Engine Enables Code Reuse

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, OpenBao's TOTP secrets engine could accept valid codes multiple times rather than strictly-once. This was caused by unexpected no…

πŸ“… Published: Aug. 9, 2025, 2:01 a.m. πŸ”„ Last Modified: Aug. 12, 2025, 11:47 a.m.
Total resulsts: 304945
Page 26 of 30,495
Β« previous page Β» next page
Filters